Errors joining samba PDC domain

Errors joining samba PDC domain

Post by Vacci » Wed, 02 Jul 2003 01:02:25



Greets everyone-

I have seen this question asked a number of times on the lists, but I
haven't found a solution that has worked for me yet.  I have created a
samba PDC, but when I try to join the domain, I get the following
error "No mapping between account names and security IDs was done.".
The PDC is running samba 2.2.8a with openldap.  I seem to be able to
authenticate vs ldap just fine, but I can't get the win2k clients to
join the domain.

So far, I have done/verified the following as possible solutions from
other postings:

- smbpasswd -e root
  smbpasswd -e administrator
  smbpasswd -a root
  smbpasswd -a administrator

- touch /usr/local/samba/private/smbpasswd
  chmod go-rwx /usr/local/samba/private/smbpasswd

- updated to the latest 2.2 branch from cvs

- ran find / -name samba (to make sure I only had one installation).

- ensured there was a machine$ account created for the client in ldap

The main thing that seems to be very wrong, is that
/usr/local/samba/private/smbpasswd remains empty and doesn't seem to
update.  Aside from that, even turning up the debugging seems to show
very little out of the ordinary.  I can include portions (or all) of
my smb.conf or output from various logs, however I didn't want to make
this post any longer than it needed to be.

Any help would be *greatly* appreciated!

-=Vaccine

 
 
 

Errors joining samba PDC domain

Post by Rob MacGrego » Wed, 02 Jul 2003 06:07:38



> I have seen this question asked a number of times on the lists, but I
> haven't found a solution that has worked for me yet.  I have created a
> samba PDC, but when I try to join the domain, I get the following
> error "No mapping between account names and security IDs was done.".
> The PDC is running samba 2.2.8a with openldap.  I seem to be able to
> authenticate vs ldap just fine, but I can't get the win2k clients to
> join the domain.

Did you follow the PDC HowTo?

Quote:> - ensured there was a machine$ account created for the client in ldap

What about creating one in the smbpasswd file?  See the PDC HowTo
document for details.

--
   Rob MacGregor (BOFH)        Oh my God! They killed init! You bastards!
       The light at the end of the tunnel is an oncoming dragon.

 
 
 

Errors joining samba PDC domain

Post by Vacci » Wed, 02 Jul 2003 12:42:48



Quote:> Did you follow the PDC HowTo?

Yes, I mostly followed the samba-LDAP-howto put out by the folks at
idealx.org, as that was closer to the setup I was trying to achieve.
I also read the PDC-howto section of the samba-howto-collection in the
samba.org docs section.

Quote:> > - ensured there was a machine$ account created for the client in ldap

> What about creating one in the smbpasswd file?  See the PDC HowTo
> document for details.

Both HowTo's said to make sure they had a UNIX account (usually in
/etc/passwd), which it does, in my case, LDAP, and then do "smbpasswd
-a -m machine_name, where machine_name is the netbios name".  I did
that, and can verify that the passwords have been updated in the
lmpassword/ntpassword fields in LDAP for the corresponding account.
However, there was nothing added to the smbpasswd file, and I still
get the same error.

Any other suggestions?

-=Vaccine

 
 
 

Errors joining samba PDC domain

Post by Rob MacGrego » Wed, 02 Jul 2003 21:52:02



> Any other suggestions?

I suppose I'd suggest you try getting it working without LDAP first.
Basically, simplify your configuration, it'll make diagnosis easier.

--
   Rob MacGregor (BOFH)        Oh my God! They killed init! You bastards!
       The light at the end of the tunnel is an oncoming dragon.

 
 
 

1. SAMBA: Joining NT Domain (User PDC or Resource PDC???)

I have been examining the DOMAIN_MEMBER.txt documentation and I have a
question.

The documentation states that you need to add NetBIOS name of the Samba
server to the NT domain on the PDC using Server Manager for Domains.

Do you add the machine to the local "Resource Domain" (which for me
Docontains only machines) or to the "User main" (which for me only
contains users)??

I ask primarily because I havent a snowballs chance in hell of getting
anyone to add something to the PDC for the user domain (HP corporate is
rather sensitive about *any* modifications in that domain) but I can add
the machine to the resource domain without any problem.

-----------------------------------------------------------------------
    John Cavanaugh                          Hewlett-Packard Company
    Project Engineer                        1400 Fountaingrove Pkwy
    EESof Division                          Santa Rosa, CA 95403-1799


                                                707-577-3948 (Fax)
-----------------------------------------------------------------------
               You can't think and hit and the same time.
                                                -- Yogi Berra
-----------------------------------------------------------------------

2. video in to video out on O2

3. Can't join domain with Samba PDC..

4. Help re Web browser on 5mx

5. Samba 2.2.1a PDC/Win2k - Problems joining domain

6. Data/Function Placement

7. W2K SP2 and Samba 2.2.1a PDC Can't Join Domain

8. Stoneage sound - where [Q]

9. can't get samba to join NT4 PDC controlled domain

10. samba joining NT PDC controlled domain

11. No PDC just Workgroup - can they be joined to a SAMBA PDC

12. join client samba on a PDC samba

13. Problem with additional samba server joining existing samba PDC